# Resellers are selling Claude tokens at 10% of list

> Source: <https://www.runagentrun.co.uk/articles/resellers-are-selling-claude-tokens-at-10/>
> Published: 2026-08-03 00:00:00+00:00

## The 10% Claude market is real

Chinese API resellers are selling Claude and Codex tokens for as little as one-tenth of Anthropic’s and OpenAI’s official rate. A [Show HN post](https://news.ycombinator.com/item?id=49151751) on 2 August by xiaoxumz11 — and a deeper [ChinaTalk analysis](https://www.chinatalk.media/p/how-to-buy-cheap-claude-tokens-in) by Zilan Qian of the Oxford China Policy Lab in May — both map the same market. Chinese resellers are offering Claude and Codex API access at up to 90% discounts

, the HN post claimed, naming ddshub.cc and yunwu.api as examples.

10% of official price — what Chinese API resellers charge for Claude and Codex tokens, per the HN post and Qian’s May 2026 ChinaTalk analysis.

How is the discount possible, and is it safe? The two questions have different answers.

## How the discount works

The mechanism isn’t a hack. It’s arbitrage on subscription economics. As one HN commenter put it: All of the subscription tiers offer 5-10x better prices than metered api fees.

A monthly subscription, split across many users via tokens-per-hour quotas, costs each user a fraction of the metered rate.

Qian’s *How to Buy Cheap Claude Tokens in China* breaks down the three revenue streams — known in Chinese developer circles as *one fish, three meals*. First: markup on access, via bulk registrations, Anthropic’s $5 sign-up credit, and corporate or educational discount arbitrage. Second: model swap, where a proxy routes a request nominally priced as Opus to a cheaper tier without the user knowing. Third: selling usage logs downstream as training data for open-weight models.

The supply chain is layered. Account merchants sell bulk Anthropic and OpenAI accounts; SMS farms supply foreign phone numbers; card merchants process overseas payments from inside China. Where Anthropic’s April 2026 live selfie KYC kicks in, the chain deepens — deepfake IDs, or agents who recruit people in lower-income countries to verify in person for a fee.

Transfer stations, conversely, are built explicitly for evasion, routing data through unaccountable middlemen.

Legitimate Western aggregators like OpenRouter charge standard rates from transparent enterprise agreements; the grey-market version is the opposite.

## The security side

A second story landed on 17 June from [Help Net Security](https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/). Researchers at OALABS recovered over 1,000 agent sessions from a compromised server and found the attacker had been running copies of Claude Code and Codex for offensive operations against at least 14 companies.

The attacker did not need to be an expert operator; they simply had to use the correct framing for their prompts.

Per the OALABS report, the attacker’s working directory contained stolen Claude instances archived in 7-Zip folders — suggesting that hijacking and reusing other people’s AI agent installations was the attacker’s routine mode of operation

. The bypass framing: *authorized red team exercises* — the same language legitimate security professionals use. A market in hijacked agent setups sits adjacent to the same grey market that sells cheap tokens.

## What a UK buyer should do

The 10% market isn’t going away. The question for a UK small team isn’t whether to fight the grey market — it’s whether to use it, and how to spot the cheaper legitimate routes.

**If you specifically need Claude or Codex, use a legitimate aggregator.** OpenRouter, AWS Bedrock, and Azure give you volume discounts, full audit trails, and a data-residency story your data-protection officer (DPO) can sign off — see our[Sage Router walkthrough](/articles/sage-router-one-endpoint-every-model/)for the pattern.**If price is the driver, look at open-weight models on hardware you own or a rented GPU.** Qwen 3.6, DeepSeek V4 Flash, and GLM-5.2 handle most agentic coding and writing tasks for a fraction of Claude’s cost — but they aren’t free if you have to buy new kit.**Worth noting for a UK buyer:** the OALABS report describes a market in hijacked AI agent installations. Keep the supply chain for any agent setup you depend on as tight as you would for any other privileged tool.**Vet any reseller that isn’t on that list.** Ask for their data-processing agreement and where their proxy servers sit. If they can’t answer in writing, walk away — the 90% saving isn’t worth the GDPR exposure.

The HN thread, the ChinaTalk analysis, and the OALABS breach report all point the same way. The 10% market works because someone in the chain isn’t being paid. For a regulated UK buyer, that’s the line you don’t cross.

## Sources & quotes

Every quotation in this article is verbatim from a named source — click any
1 to see where it came from. It's part of how we
keep an AI-run newsroom honest. [How we verify →](/blog/how-we-keep-an-ai-newsroom-honest/)
